Toss Australia Pty Ltd (referred to as “TOSS AU,” “we,” “us,” or “our”) is committed to protecting your privacy. We comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) in handling your personal information. As an operator of a financial app in Australia offering services like money transfers, personal data management, and reward programs, we collect and use personal information to provide these services. In doing so, we promise to:
This Privacy Policy explains what personal information we collect, how we use and disclose it, how you can access or correct your information, and how to make a privacy complaint. “Personal information” in this Policy means any information or opinion about you where you are identified or reasonably identifiable. By using our services or providing personal information to us, you consent to the collection, use, and disclosure of that information in accordance with this Privacy Policy and any applicable laws.
We collect various types of personal information in order to operate our services and fulfill legal requirements. The types of personal information we may collect include:
We aim to only collect information that is reasonably necessary for our functions or activities. If you choose not to provide certain information we request (or if you request to deal with us anonymously or under a pseudonym), we may not be able to provide you with our services or respond effectively to your needs. Due to the nature of our financial services and legal obligations (for example, anti-money laundering laws), it is generally impracticable for us to serve customers who are not identified to us.
Directly from You: In most cases, we collect personal information directly from you. You provide information to us when you create an account, fill in forms or application fields in our app, including before completing KYC or onboarding, use our services, communicate with us (such as via customer support inquiries, email, or social media), or respond to our surveys or promotions. For example, we obtain personal details during sign-up and identity verification, and we gather transaction information when you make a transfer or use other features.
Automatically from Your Use of Services: When you use our mobile app or website, we automatically collect certain technical and usage information through tools like cookies and similar technologies. This includes data such as your IP address, device type, operating system, browser settings, and activity logs (e.g., pages or screens you view, buttons you click). We use this information to understand how users interact with our services, to personalize your experience, and to maintain and improve our platform’s functionality and security. (See Cookies and Analytics below for more detail on how we use cookies.)
From Third Parties: In some cases, we may obtain personal information about you from third-party sources, such as:
If we receive personal information that we didn’t request (unsolicited information), we will determine if it is necessary for our purposes. If not, we will promptly destroy or de-identify that information, provided it is lawful and reasonable to do so. We will not keep unsolicited personal data unless it is relevant to our services or we are required to retain it.
Cookies and Analytics: We use cookies and similar tracking technologies on our website to enhance your user experience and analyze usage of our services. Cookies are small text files that are placed on your device by websites. They help us remember your preferences and understand how visitors use our site. For example, cookies enable features like keeping you logged in, and they help us gather aggregate data about site traffic (such as number of visitors, popular pages, and user location on a general level). This data collected via analytics is typically anonymous and does not identify you personally. You can control or disable cookies through your web browser settings (for example, you may choose to block or delete cookies). However, please note that if you disable cookies, some features of our website or services may not function properly. By using our site without disabling cookies, you consent to our use of cookies as described in this Policy.
We collect and hold personal information about you so that we can effectively conduct our business and deliver the services you expect. We may use your personal information for purposes including:
We will not use your personal information for purposes other than those outlined in this Policy unless: (a) you consent to the new use, or (b) it is required or permitted by law. If we ever need to use your information for a completely new, unrelated purpose, we will seek your consent or provide you with notice as required.
From time to time, we may use your personal information to send you marketing communications about our services or new products, or about services of third parties that we partner with (for example, promotions jointly offered with a partner bank or merchant). We may contact you for marketing via email, in-app notifications, SMS, phone, or other channels you have agreed to. We will only send you direct marketing: (i) with your consent, or (ii) if you would reasonably expect to receive such communications from us (for example, because you have signed up for our services), and in each case we will provide a simple way to opt out. Every marketing email or message from us will include an unsubscribe option (such as an “unsubscribe” link or instructions to opt out). If you have an online account with us, you may also adjust your communication preferences in your profile settings, or you can always opt out by contacting us. We will respect your choice and ensure you are not sent further marketing material if you opt out. Opting out of marketing communications will not affect your ability to use our services.
We do not share your personal information with third-party companies for their own marketing purposes unless you have expressly consented to that sharing. In other words, we will never sell or rent your personal details to other companies for marketing or advertising. We may share marketing communications from our partners within our own messages (for example, including a special offer from a partner in a newsletter), but those communications will come from us and will be under our control. If you consent to receive marketing from a third party that is facilitated through our platform, that third party’s privacy terms will apply to their use of your information.
Please note that transactional or service communications (such as payment confirmations, account alerts, etc.) are not considered “marketing” – you will continue to receive those as part of using our services, even if you opt out of marketing messages.
We take your privacy seriously. We do not disclose your personal information to others except as needed to run our business or as required by law. The types of entities we might share personal information with include:
These service providers are only given the information necessary for them to perform the contracted service. They are not permitted to use your information for any other purpose and are bound to keep your details confidential and secure. We require our service providers to handle personal information in compliance with applicable privacy laws and this Policy.
In any case of sharing, we will aim to disclose only what is necessary for the purpose at hand and ensure that the recipient will safeguard the information. Aside from the parties listed above, we will not give any other third parties access to your personal information unless it is required by law or we have your permission.
Yes, some of the personal information we collect may be transferred and stored overseas. TOSS AU is part of a global company, and we engage certain service providers located outside of Australia. For example, we may share data with:
When we transfer personal information outside Australia, we take reasonable steps to ensure the overseas recipient will handle the information in a manner consistent with the APPs and this Privacy Policy. For example, we may contractually require the overseas recipient to comply with Australian privacy standards, or we may ensure they are subject to privacy laws that offer similar protection. We will not send your data to a country unless one of the following applies: (a) the recipient is governed by privacy laws or binding schemes substantially similar to Australia’s (or we have otherwise ensured appropriate safeguards); (b) you consent to the transfer (after being informed that Australian protections may not apply); or (c) the transfer is otherwise permitted by law.
Important: If we transfer your personal information overseas at your request or with your consent, please understand that the overseas entity may not be bound by Australian privacy law. This means, for such transfers, we may not be accountable under the Privacy Act for any mishandling of your information by that overseas recipient. However, we will seek to minimize this scenario and will only proceed with an overseas transfer in this way if it is necessary and you have explicitly agreed.
Security Measures: We understand the importance of keeping your personal information secure. We have implemented a range of technical and organizational security measures to protect your data from misuse, interference, loss, and unauthorized access, modification or disclosure. These measures include (but are not limited to):
While we strive to protect your information, please note that no method of transmission over the internet or electronic storage is completely secure. However, we regularly review our security practices to adapt to new threats and to meet or exceed industry standards (such as encryption protocols and cybersecurity frameworks). If a data breach does occur that is likely to result in serious harm, we will notify you and the relevant authorities as required by law.
Storage and Retention: Personal information that we collect is generally stored in electronic form in secure databases. Any paper records (if generated) are kept in locked, secure areas. We retain personal information only for as long as necessary to fulfill the purposes we collected it for, including for any legal, accounting, or reporting requirements. For example, we might keep some transaction records for a number of years to comply with financial laws. When we no longer need your personal information for our business or legal purposes, we will take reasonable steps to destroy it or de-identify it.
Accessing Your Information: You have the right to request access to the personal information we hold about you. To do so, please contact our Privacy Officer using the contact details in the section below. In order to protect your privacy, we will need to verify your identity before giving you access – for example, we might require you to make the request in writing and provide specific identification information. We will aim to respond to your request within 30 days as required by the Privacy Act. If for some reason we refuse access (for example, if giving access would unreasonably impact someone else’s privacy or if it would violate a law), we will provide you with written reasons for the refusal and inform you of any available review mechanisms. In general, we will grant access unless a specific legal exception applies.
Usually, there is no charge for an access request. However, if your request involves a significant amount of work (e.g., retrieving a large volume of data from backup archives), we may charge a reasonable fee to cover the cost of providing the information (such as staff time or photocopying). We will let you know in advance if a fee might apply, so you can decide whether to proceed. We will not charge for simply making the request or for correcting information.
Correcting Your Information: We take reasonable steps to ensure that the personal information we collect is accurate, up-to-date, and complete. If you believe that any information we hold about you is incorrect, incomplete, or not current, you have the right to request that we correct it. You can do this by contacting us with the details of the information to be corrected. Where reasonable, and after verifying your identity, we will correct the information as requested. If the data has been disclosed to a third party as part of our processes and the correction is relevant to them, upon your request we will also notify that third party of the correction within a reasonable time.
In the unlikely event we disagree with the change you have requested (for instance, if we believe the information we have is accurate), we will let you know our reasons. You then have the right to request that we attach a note to the information stating that you claim it is inaccurate, out-of-date, incomplete, or irrelevant. We will always respond to your correction requests and take reasonable steps to resolve any issues. Our goal is to maintain your information as accurate and up-to-date as possible, so we appreciate you keeping us informed of any changes (such as updated contact details).
We value your privacy and strive to address any concerns you have. If you: (a) have any questions or feedback about this Privacy Policy or our privacy practices, (b) want to access or correct your personal information, or (c) have a complaint about how we have handled your personal information, please contact us.
Contacting TOSS AU: The easiest way to reach us is by emailing our Privacy Officer at global-support@toss.im. You can also send your requests or complaints in writing to:
Privacy Officer, TOSS AU
Email: global-support@toss.im
Please provide as much detail as possible about your question or issue. If you are making a complaint, include details such as what happened, when, and what you would like us to do. We will acknowledge receipt of your complaint and work to investigate and respond to you as soon as possible. We aim to resolve all complaints in a timely and fair manner. Our complaints handling process involves investigating the issue, addressing any problems in our processes or policies, and responding to you with the outcome and any actions we will take. We will typically respond to complaints in writing within a reasonable timeframe. If needed, we may get in touch with you to gather more information about your complaint.
If you are not satisfied with our response to your privacy query or complaint, you have the right to escalate the matter to an external authority. In Australia, you can contact the Office of the Australian Information Commissioner (OAIC). The OAIC is the independent regulator for privacy and can investigate complaints about the handling of personal information.
Contact details for the OAIC:
We encourage you to let us try to resolve the issue first, but you are free to contact the OAIC at any time.
We may update this Privacy Policy from time to time to reflect changes in our practices, services or legal obligations. When we make changes, we will post the updated Policy on our website and change the “Last updated” date at the top or bottom of the Policy. If there are material changes that significantly affect your rights or how we handle personal information, we will take reasonable steps to notify you – for example, by email, by prominent notice on our app or website, or other means. We encourage you to check our website periodically to ensure you are aware of the most current Privacy Policy. Your continued use of our services after any update will constitute your acknowledgment of the amended Privacy Policy.